3 ms·
I created an HAProxy configuration that should be equivalent to the nginx configuration within the Signal-TLS-Proxy repository: https://gist.github.com/TimWoll
by TimWolla 6y ago
I created an HAProxy configuration that should be equivalent to the nginx configuration within the Signal-TLS-Proxy repository:
https://gist.github.com/TimWolla/457c45dfccde26fc674dde4b3c7235c1 https://gist.github.com/TimWolla/457c45dfccde26fc674dde4b3c7...
I could not test it with the Signal client yet, because the Beta is not yet available for me. However I verified that the nested TLS works using openssl and netcat.
- remram 6y agoTheir proxy seems to just be nginx, I'm surprised they didn't just share nginx or apache configurations. Most people with a box suitable for running this are probably already running a web server, so there's no reason they should be proxying from their existing web server to this dockerized server which just proxies to Signal. Looking into their repo, they also appear to be building an nginx image from docker.io/ubuntu:20.04 instead of using docker.io/nginx. They are also running two separate nginx processes. I wonder how they ended up with this weird intricate setup. I would be glad to help if they offered straightforward instructions.
- jlund 6y agoThe Nginx configs use modules that are not compiled by default, so most preexisting Nginx binaries in mainstream distros won't work.
- 2cb 6y agoThis is correct, just set one of these up and it uses extra Nginx plugins. Also the way they’ve done it makes it incredibly easy for anyone who isn’t a tech expert with a web server to still help out with a $5 domain and a $5 VPS. You literally run three commands and it’s done. They want as many people as possible running these so blocking them all is as difficult as possible. It’s the smartest approach to have a low barrier to entry for something like this.